---
id: CVE-2026-92626
title: "Control iD iDSecure versions prior to\_4.8.3.0 are affected by an unauthenticated\_Denial of Service.\n\n\nThe /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled n…"
summary: "Control iD iDSecure versions prior to\_4.8.3.0 are affected by an unauthenticated\_Denial of Service.\n\n\nThe /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled n…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: Control iD
product: iDSecure
affected:
  - iDSecure < 4.8.3.0
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:18:42.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92626'
references:
  - url: 'https://www.tenable.com/security/research/tra-2026-56'
    label: vulnreport@tenable.com
tags:
  - nvd
  - cve.org
epss: 0.0046
epssPercentile: 0.37261
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T17:35:07.266483Z'
ingestedAt: '2026-09-16T15:58:38.774Z'
---

## Overview

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.


The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
